Private equity giant Apollo Global Management has confirmed that hackers stole personal data, including Social Security numbers, from its cloud systems in a social engineering attack that occurred in early July.
The New York-based firm, which manages $938 billion in assets, disclosed the breach in a letter filed with California’s attorney general. Apollo’s HR chief Matthew Breitfelder said attackers used social engineering techniques to gain unauthorized access to the company’s cloud environment between July 6 and July 10.
Part of a Wider Campaign Against Financial Firms
The breach is linked to a broader hacking campaign targeting financial services firms across the United States. Google’s Threat Intelligence team warned in July that a group tracked under multiple names, including Falcon, Helix, Pink, and Redact, was targeting private equity companies and other financial giants. Apollo was named alongside Blackstone, Bridgewater, and Bain Capital as firms that had been targeted, though it was unclear at the time whether any had been successfully breached.
The hackers use social engineering tactics that involve calling employees and posing as IT helpdesk or support staff. Victims are tricked into entering passwords and multi-factor authentication codes on spoofed login pages, which gives attackers access to corporate networks. According to Google, some of the attacks yielded ransoms as high as $750,000.
Social Security Numbers and Personal Data Stolen
Apollo said the stolen data includes names, dates of birth, contact information including home addresses, and Social Security numbers. The company did not specify whether the affected individuals are Apollo employees or people associated with companies in its portfolio. Apollo has approximately 5,000 employees as of early 2026, according to public regulatory filings.
Apollo’s shares fell 5.7 percent following the disclosure. The company said it has found no evidence that the stolen information has been publicly posted or used for identity theft or fraud. However, cybersecurity experts note that stolen data can be held privately and exploited months or years after a breach, making the absence of visible misuse a poor indicator of actual risk.
The incident underscores the growing vulnerability of financial firms to social engineering attacks, which bypass technical security controls by targeting human behavior. Google recommended that financial firms implement stricter verification protocols for IT support calls and invest in employee security awareness training to defend against these tactics.
discussion